ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0069×

68 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
GroupMuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.

T1559.001
Component Object Model
GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

T1559.002
Dynamic Data Exchange
GroupMuddyWater

MuddyWater has used malware that can execute PowerShell scripts via DDE.

T1560.001
Archive via Utility
GroupMuddyWater

MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded.

T1566
Phishing
GroupMuddyWater

MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1566.002
Spearphishing Link
GroupMuddyWater

MuddyWater has sent targeted spearphishing e-mails with malicious links.

T1567.002
Exfiltration to Cloud Storage
GroupMuddyWater

MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.

T1571
Non-Standard Port
GroupMuddyWater

MuddyWater has used ports 8043 and 8848 for botnet C2 communication.

T1573.001
Symmetric Cryptography
GroupMuddyWater

MuddyWater has used AES to encrypt C2 responses.

T1574.001
DLL
GroupMuddyWater

MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.

T1583.001
Domains
GroupMuddyWater

MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations.

T1583.006
Web Services
GroupMuddyWater

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.

T1588.001
Malware
GroupMuddyWater

MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals.

T1588.002
Tool
GroupMuddyWater

MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment.

T1590.004
Network Topology
GroupMuddyWater

MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.

T1684.001
Impersonation
GroupMuddyWater

MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell.

T1685
Disable or Modify Tools
GroupMuddyWater

MuddyWater can disable the system's local proxy settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.